ss-coding-workflow
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from external execution plans and plain-language change instructions.\n- Ingestion points: Processes input from user-provided file paths or text instructions as defined in the
Inputssection ofSKILL.md.\n- Boundary markers: The skill does not implement specific delimiters or boundary markers to isolate untrusted user data from the agent's internal logic.\n- Capability inventory: The orchestrator invokes sub-skills that possess capabilities for file system modification (ss-coding) and network communication via CLI tools (ss-create-pr).\n- Sanitization: No explicit sanitization or filtering is performed on the input content before it is passed to the coding and delivery sub-skills.
Audit Metadata